Auditing Network Traffic and Privacy Policies in Oculus VR

06/09/2021
by   Rahmadi Trimananda, et al.
0

Virtual reality (VR) is an emerging technology that enables new applications but also introduces privacy risks. In this paper, we focus on Oculus VR (OVR), the leading platform in the VR space, and we provide the first comprehensive analysis of personal data exposed by OVR apps and the platform itself, from a combined networking and privacy policy perspective. We experimented with the Quest 2 headset, and we tested the most popular VR apps available on the official Oculus and the SideQuest app stores. We developed OVRseen, a methodology and system for collecting, analyzing, and comparing network traffic and privacy policies on OVR. On the networking side, we captured and decrypted network traffic of VR apps, which was previously not possible on OVR, and we extracted data flows (defined as <app, data type, destination>). We found that the OVR ecosystem (compared to the mobile and other app ecosystems) is more centralized, and driven by tracking and analytics, rather than by third-party advertising. We show that the data types exposed by VR apps include personally identifiable information (PII), device information that can be used for fingerprinting, and VR-specific data types. By comparing the data flows found in the network traffic with statements made in the apps' privacy policies, we discovered that approximately 70 disclosed. Furthermore, we provided additional context for these data flows, including the purpose, which we extracted from the privacy policies, and observed that 69 apps.

READ FULL TEXT

page 2

page 12

research
08/14/2023

BehaVR: User Identification Based on VR Sensor Data

Virtual reality (VR) platforms enable a wide range of applications, howe...
research
10/06/2019

Large-scale Mobile App Identification Using Deep Learning

Many network services and tools (e.g. network monitors, malware-detectio...
research
11/15/2021

Tracking in apps' privacy policies

Data protection law, including the General Data Protection Regulation (G...
research
04/07/2022

Goodbye Tracking? Impact of iOS App Tracking Transparency and Privacy Labels

Tracking is a highly privacy-invasive data collection practice that has ...
research
04/13/2022

Are You Really Muted?: A Privacy Analysis of Mute Buttons in Video Conferencing Apps

Video conferencing apps (VCAs) make it possible for previously private s...
research
12/23/2021

Statistical Feature-based Personal Information Detection in Mobile Network Traffic

With the popularity of smartphones, mobile applications (apps) have pene...
research
07/26/2022

Exploring the Unprecedented Privacy Risks of the Metaverse

Thirty study participants playtested an innocent-looking "escape room" g...

Please sign up or login with your details

Forgot password? Click here to reset